Settings

Theme

Hacking CloudKit: How I accidentally deleted your Apple shortcuts

labs.detectify.com

19 points by xhruso00 4 years ago · 2 comments

Reader

chrisandchris 4 years ago

> But remember that I mentioned different APIs talked with CloudKit differently?

As this sentence is the cause of most the bugs in the post I begin to question how they implemented their gateway so that a different endpoint results in a totally different authorization scope. That just screams „auth bug“.

epaga 4 years ago

Wow, I remember this happening! That is truly funny to me that it was because of a security researcher accidentally triggering this massive bug.

Great write up, and kudos to apple for not suing him but paying out the bug bounties.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection